
🟠 CVE-2026-29064 - High Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf... https://www.thehackerwire.com/vulnerability/CVE-2026-29064/ https://t.co/a0IrZ5eRe8
Post summary
A new high‑severity path traversal vulnerability (CVE‑2026‑29064) affecting Zarf versions 0.54.0–0.73.1 has been disclosed, detailing how a specifically crafted archive can exploit directory traversal during extraction.



